Lucene search

K
osvGoogleOSV:GHSA-XQW9-FFX7-G998
HistoryMay 17, 2022 - 2:37 a.m.

phpMyAdmin cookie-attribute injection

2022-05-1702:37:29
Google
osv.dev
20
phpmyadmin
cookie-attribute injection
vulnerability
4.6.x
crafted uri

EPSS

0.002

Percentile

60.9%

phpMyAdmin 4.6.x before 4.6.3, when the environment lacks a PHP_SELF value, allows remote attackers to conduct cookie-attribute injection attacks via a crafted URI.